PT-2010-2228 · Roundcube · Roundcube

Published

2010-01-29

·

Updated

2015-08-24

·

CVE-2010-0464

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Roundcube versions 0.3.1 and earlier
Description The issue makes it easier for remote attackers to determine the network location of the webmail user by logging DNS requests, as the web browser is not requested to avoid DNS prefetching of domain names contained in e-mail messages.
Recommendations For versions 0.3.1 and earlier, consider configuring the web browser to avoid DNS prefetching of domain names contained in e-mail messages as a temporary workaround until a patch is available.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-0464

Affected Products

Roundcube